Vulnerability
Advisory/Mitigation
Campaign
Operation CameraSwarm exploitation of Dahua authentication-bypass flaws
Updated 19.08.2026 21:09
Case score 78
Why this score?
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 78
- Main story score
- 78
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 2
Top contributors
- Vulnerability Primary anchor for the exploited Dahua authentication-bypass flaws. main
- Campaign Direct exploitation evidence and operational fallout for the same CVEs. context
- Advisory Mitigation Current KEV tracking and required mitigation guidance for the same CVEs. context
Members 3
First seen 19.08.2026 14:34
Latest activity 19.08.2026 21:09
Overview
Attackers used **CVE-2021-33044** and **CVE-2021-33045** in **Operation CameraSwarm** to compromise more than **14,530 Dahua devices** between June 17 and July 22, 2026, combining the authentication-bypass flaws with credential attacks and a P2P relay path. Hunt.io said the operation left **1,923 cameras** configured with a persistent account and reached **283 cameras** through the P2P route, with confirmed compromises concentrated in **Ukraine** and **Russia**.
**CISA** still lists both Dahua flaws in the **Known Exploited Vulnerabilities** catalog and directs operators to apply vendor mitigations or discontinue use if mitigations are unavailable. **Dahua** says fixed firmware is available, so the current picture is confirmed exploitation followed by ongoing patch-and-remove pressure for exposed camera fleets.
Latest development Open development history Hunt.io discloses Operation CameraSwarm against Dahua devices Hunt.io says Operation CameraSwarm compromised more than 14,530 Dahua devices between June 17 and July 22, 2026 by combining credential attacks, CVE-2021-33044, CVE-2021-33045, and a P2P relay path; the researchers say 1,923 cameras were configured with a persistent account, 283 were reached through P2P, and confirmed compromises were concentrated in Ukraine and Russia. Users of affected Dahua products are advised to install the corresponding fix software or newer firmware, and ITRES Labs recommends disabling P2P where it is not required and checking firmware against the vendor's download site.
-
CISA keeps Dahua authentication-bypass flaws in the KEV catalog
CISA kept CVE-2021-33044 and CVE-2021-33045 listed in the Known Exploited Vulnerabilities catalog for Dahua IP camera authentication-bypass vulnerabilities and directed operators of affected Dahua cameras and related products to apply vendor mitigations or discontinue use if mitigations are unavailable.
Attackers used **CVE-2021-33044** and **CVE-2021-33045** to access **Dahua** devices during **Operation CameraSwarm**, combining the authentication-bypass flaws with credential attacks and a peer-to-peer relay path. Hunt.io said the operation compromised **more than 14,530 Dahua devices** between June 17 and July 22, 2026, left **1,923 cameras** configured with a persistent account, and reached **283 cameras** through the P2P path. Confirmed compromises were concentrated in **Ukraine** and **Russia**, and the activity was reconstructed from a **407 MB** exposed working directory containing **2,616 files** across **234 subdirectories**.
The two Dahua flaws affect device login by letting attackers bypass identity checks, and they remain operationally relevant because both are tracked as known exploited vulnerabilities. Affected product scope in the available material spans Dahua IP cameras and related products, with additional listed families including video intercom, NVR, XVR, PTZ dome, and thermal camera devices. Available material also mentions **CVE-2024-39943** and **CVE-2025-31702**, but it does not establish that those CVEs explain the P2P behavior used in this operation.
**CISA** continues to keep **CVE-2021-33044** and **CVE-2021-33045** in the **Known Exploited Vulnerabilities** catalog and directs operators to apply vendor mitigations or discontinue use if mitigations are unavailable. **Dahua** says fixed firmware is available, while severity scoring differs between Dahua's advisory at **8.1 CVSS** and NVD at **9.8 CVSS** for each flaw. The immediate defensive priority is to patch or replace exposed Dahua devices and review unnecessary P2P exposure on fleets that may still be reachable through the same paths.
Signals
Impact signals
Exploitation
CVEs/products
Geographic context
Remediation
Status
Tooling context
3 toolsTechnical intelligence
Existing Case dataMember happenings
Vulnerability
Dahua cameras authentication-bypass vulnerabilities (multiple vulnerabilities)
Exploitation
Active Exploitation
CVSS
9.8 Critical
Patch
Patch Available
Vulnerability
Dahua cameras authentication-bypass vulnerabilities (multiple vulnerabilities)
Exploitation
Active Exploitation
CVSS
9.8 Critical
Patch
Patch Available
Advisory/Mitigation
CISA KEV guidance for Dahua IP camera authentication-bypass flaws (CVE-2021-33044, CVE-2021-33045)
Exploitation
Active Exploitation
CVSS
9.8 Critical
Urgency
Immediate
Patch
Patch Available
Advisory/Mitigation
CISA KEV guidance for Dahua IP camera authentication-bypass flaws (CVE-2021-33044, CVE-2021-33045)
Exploitation
Active Exploitation
CVSS
9.8 Critical
Urgency
Immediate
Patch
Patch Available
Campaign
Operation CameraSwarm campaign targeting Dahua devices
Campaign
Active
Patch
Patch Available
Campaign
Operation CameraSwarm campaign targeting Dahua devices
Campaign
Active
Patch
Patch Available